Executive Overview
For years, cybersecurity professionals and intelligence agencies have issued stark warnings about the hidden dangers lurking inside cheap, generic Android TV boxes. Sold widely across major e-commerce platforms like Amazon, Best Buy, and Newegg, these devices promise consumers an enticing shortcut: unlimited, subscription-free streaming of live television, movies, and premium sports for a meager, one-time fee. Yet, beneath their innocuous consumer-facing interfaces lies a darker reality. Security researchers have long known that these bargain streaming sticks secretly hijack home networks, renting out residential Internet bandwidth to anonymous third parties.
However, a groundbreaking investigation by threat intelligence firm Bitsight reveals that the exploitation goes far beyond passive bandwidth laundering. According to a comprehensive analysis released by Bitsight threat researcher Pedro Falé, popular generic streaming hardware—specifically units under the brand name H96—are deeply embedded in a sprawling, sophisticated digital advertising fraud operation.
Rather than merely serving as quiet relay nodes, these pre-infected devices systematically spoof their digital fingerprints, masquerading as high-end mobile phones manufactured by tech giants like Samsung, Vivo, Huawei, and Xiaomi. Once disguised, the devices execute automated, programmatic click-fraud routines against a massive network of AI-generated websites. Controlled by a mainland Chinese entity known as Zhejiang Fengwo IoT Technology Co., Ltd. (operating under the Fengwo Group), this ingenious ecosystem leverages visual programming tools, computer vision, and machine reasoning to pull in an estimated $50,000 per day from unsuspecting ad networks and online merchants.
This multi-faceted cybercriminal operation turns living room entertainment systems into an unwitting botnet. When a user actively watches television, the device acts as a silent proxy; the moment the TV is switched off, the box springs into full-scale ad-fraud mode. Despite repeated warnings from the FBI and private security analysts, the international supply chain continues to flood retail markets with unverified, pre-infected Internet of Things (IoT) hardware, posing a severe threat to enterprise networks, domestic privacy, and the integrity of the digital advertising ecosystem.
Detailed Chronology: Unmasking the H96 and Fengwo Group Conspiracy
The anatomy of this massive ad fraud enterprise came to light through a combination of forensic serendipity and meticulous threat hunting. The investigation began when Pedro Falé, a seasoned threat researcher at Bitsight, seized an unexpected opportunity: he registered an expired domain name that had historically served as a critical telemetry nexus for the popular H96 line of Android TV boxes.
1. The Accidental Breakthrough and Spoofed Telemetry
Historically, the expired domain had functioned as a collection point for device diagnostics, periodically sucking in deep hardware profiles and the complete inventory of installed apps from tens of thousands of H96 streaming sticks deployed in households worldwide. Upon re-activating the domain, Falé expected to see a predictable stream of telemetry data originating from fixed, living-room-based Android television hardware.

Instead, what he discovered was an architectural anomaly. Nearly all of the connected streaming boxes were transmitting data that flatly contradicted their physical reality. The device logs explicitly claimed that the communicating entities were not static television peripherals, but rather mobile phone models produced by top-tier smartphone manufacturers.
"We noticed something was wildly wrong," Falé told KrebsOnSecurity. "Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.’”
A deeper inspection of the software packages driving these devices revealed the presence of two identical, pre-installed applications. Forensic tracing tied these applications directly to Zhejiang Fengwo IoT Technology Ltd, a mainland China-based enterprise founded in 2019 that manages an expansive ad-publishing portfolio under the Fengwo Group banner. Bitsight’s telemetry trace (TRACE) successfully unmasked a network of shell identities scattered across Hong Kong, Singapore, and single-person corporate entities used to siphon off monetization revenues, ultimately tying the entire scheme back to Zhejiang Fengwo.
2. The AI-Generated Web Ecosystem
With the apps identified, Bitsight mapped out how the infrastructure operated. The H96 devices served as a captive, highly distributed traffic generation source designed to visit and interact with a sprawling network of sham websites operated by the Fengwo Group.
These websites were far from typical low-effort spam pages. They featured sophisticated, machine-generated news articles, high-resolution graphics, and editorial content spanning a vast array of topics, including finance, health, education, gaming, music, and food blogs. However, Falé’s team uncovered a critical security control: none of these AI-generated websites displayed advertisements unless the visiting client device matched the specific, spoofed mobile device profile transmitted by the infected H96 TV boxes. The web properties were meticulously engineered to interact exclusively with fake mobile device traffic, shielding their fraudulent mechanics from standard desktop browsers and casual human users.
3. Democratizing Fraud: The Blockly Implementation
One of the most innovative and alarming aspects of the Fengwo Group’s infrastructure is its operational efficiency. The enterprise’s primary cloud portal, fwgcloud[.]com, boldly claims to be "redefining the boundaries of human-AI interaction," boasting a staggering catalogue of over 120,000 "AI digital humans" available to rent for tasks ranging from emotional companionship to 24/7 customer service.

However, SSL certificate analysis and internal wiki leaks connected this polished public facade directly to the ad-fraud infrastructure. Bitsight discovered that Fengwo employees utilized an internal, proprietary implementation of Blockly—an open-source, visual programming language originally developed by Google to teach children how to write code by dragging and dropping interlocking visual blocks.
By integrating Blockly into their operational pipeline, the Fengwo Group successfully democratized malware deployment. Low-skilled operators within the organization did not need an advanced understanding of computer science, network protocols, or JavaScript execution environments. Instead, they could simply drag and drop visual code blocks to define custom ad-fraud routines.
Once an operator finalized a routine within the Blockly editor, the system automatically compiled and exported the logic as JavaScript, uploading it directly to Amazon S3 buckets. As Bitsight noted in its formal technical report:
"An operator can drag blocks together in their Blockly editor to define each fraud routine, given a task type. Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use."
Internal communications recovered by researchers highlighted the economic brilliance of this strategy from an adversary’s perspective. One Fengwo developer remarked that building the infrastructure required only a small cadre of highly skilled developers to construct core template execution-unit images. Everyday operators could then spin up new fraud routines using those templates with minimal technical proficiency, dramatically driving down operational overhead while maximizing output.
4. Automated Computer Vision and Human-Like Interaction
To bypass modern ad-fraud detection mechanisms that rely on behavioral heuristics and mouse-movement tracking, the Fengwo Group integrated advanced automation into its H96 payloads. When an H96 streaming stick was selected for an ad-fraud task, it downloaded a specific Blockly-generated module designed to silently launch an embedded web browser, navigate complex site hierarchies, manage tabs, and interact with web elements.

To ensure these bot-driven sessions appeared entirely authentic to ad networks, the Fengwo Group fused three distinct vision and reasoning systems into a unified interface. This multi-layered visual engine allowed the headless bots to accurately identify native advertisements embedded within the AI-generated web pages and navigate the site with human-like precision—scrolling, pausing, and clicking precisely where a real consumer would.
Supporting Context & Metrics: The Duality of the Botnet
Bitsight’s telemetry data exposed a fascinating operational rhythm governing how these compromised TV boxes divide their computational labor between two distinct criminal enterprises: residential proxy laundering and programmatic ad fraud.
The HDMI Switch: Proxy by Day, Ad Fraud by Night
Through meticulous traffic analysis, Bitsight observed that individual H96 devices dynamically shifted their operational profiles depending on the physical state of the television set to which they were connected.
- When the TV is On: If the device detects an active HDMI signal—indicating that a human user is sitting in front of the television actively streaming video content—the box drops its ad-fraud tasks and transitions into a high-capacity residential proxy node.
- When the TV is Off: The moment the television is powered down, the device abandons proxy routing and shifts back into an aggressive ad-fraud worker, waiting for new task assignments from the cloud.
Security researchers believe this operational trade-off is a necessity born of resource constraints. Ad-fraud execution—particularly involving headless browsers, computer vision engines, and multi-tab web navigation—is intensely resource-intensive. Running these processes simultaneously with high-bandwidth video streaming would severely degrade the performance of the streaming box, immediately alerting the consumer that something was amiss. By restricting intensive ad-fraud tasks to idle hours when the television is dark, the botnet operators maintain a clever illusion of normal device operation.
Scale, Revenue, and the "AI Digital Human" Smokescreen
Tracking approximately 38,000 active H96 TV boxes globally phoning home to the retired Fengwo telemetry domain, Bitsight conservatively estimated that this single channel generates close to $50,000 per day in fraudulent ad revenue. Crucially, this figure excludes the substantial secondary income generated through the simultaneous renting out of residential proxy bandwidth. Furthermore, researchers emphasize that this calculation represents a lower-bound estimate derived from telemetry data associated with just one core, older domain.
Regarding the Fengwo Group’s public claims of managing over 120,000 "AI digital humans," Bitsight’s report concludes that this boastful figure is likely a clever marketing smokescreen designed to cloak malicious infrastructure beneath a veneer of legitimate artificial intelligence enterprise software.

"Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size," Falé wrote. "This could also be the case here."
When KrebsOnSecurity attempted to reach out to the Fengwo Group for comment via the contact email listed on fwgcloud[.]com, the inquiry bounced back immediately with an automated delivery failure notice: "Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now." It appears the Fengwo Group’s vaunted digital workforce does not extend to customer service or media inquiries.
Official Statements and Industry Warnings
The findings from Bitsight arrive against a backdrop of escalating warnings issued by international law enforcement and cybersecurity agencies regarding the systemic risks posed by cheap, unverified Internet of Things (IoT) hardware.
The FBI’s Standing IoT Warning
In official advisories, the Federal Bureau of Investigation (FBI) has explicitly warned consumers and enterprises about the dangers of integrating unvetted, smart home devices into domestic and office networks. The bureau noted that inexpensive streaming sticks and digital photo frames purchased from obscure online vendors frequently arrive pre-infected with proxy software and administrative backdoors.
These backdoors transform home routers into transit points for criminal enterprises, enabling cybercriminals to route malicious traffic—ranging from credential-stuffing attacks and financial fraud to large-scale distributed denial-of-service (DDoS) campaigns—directly through residential IP addresses, tying illicit activities back to the homeowner’s physical doorstep.
The Broader Botnet Ecosystem: Kimwolf and Beyond
The H96 and Fengwo Group operation is far from an isolated incident. In January of this year, proxy tracking and threat intelligence firm Synthient published a landmark investigation exposing how complex botnets—such as the notorious Kimwolf botnet—rapidly enslaved millions of generic TV boxes worldwide.

Synthient’s research detailed how these botnets exploited a dangerous intersection of software vulnerabilities: weaknesses baked into the pre-installed residential proxy applications combined natively with firmware-level backdoors embedded within the cheap Android builds supplied by off-brand manufacturers. Once inside, these botnets established persistent local network persistence, quietly mapping connected smart devices and turning home local area networks into staging grounds for cyberattacks.
Future Outlook: Securing the Living Room
As the convergence of cheap hardware manufacturing, generative artificial intelligence, and automated cybercrime matures, the traditional threat landscape has expanded directly into consumer living rooms. The discovery of the Fengwo Group’s Blockly-driven ad-fraud operation demonstrates how low-barrier development tools are being weaponized to industrialize digital fraud at a scale previously reserved for advanced nation-state actors.
Actionable Guidance for Consumers and Enterprises
Security experts emphasize that safeguarding personal and enterprise networks against these pervasive threats requires a fundamental shift in purchasing behavior and digital hygiene:
- Stick to Reputable Brands: Consumers should strictly avoid unverified, ultra-cheap streaming sticks sold by nameless third-party storefronts on major e-commerce platforms. Major brand-name streaming hardware (such as Apple TV, Roku, Amazon Fire TV, and Google Chromecast) undergo stringent security audits and maintain verified supply chains.
- Verify Operating System Authenticity: Google provides official documentation enabling consumers to verify whether an Android TV device runs the genuine, Play Protect-certified Android TV OS. If a device relies on a custom, unverified fork of Android loaded with sideloaded app repositories, it should be disconnected immediately.
- Consult Public Threat Databases: Organizations like Synthient maintain public repositories—such as community-maintained CSV lists of known malicious IoT products—cataloging streaming boxes, digital photo frames, and smart home appliances documented as shipping with pre-installed proxy software and backdoors.
- Isolate IoT Devices: For households and small businesses utilizing smart home appliances, network segmentation is critical. Placing IoT hardware on an isolated guest Wi-Fi network prevents compromised devices from scanning local corporate resources, accessing Network-Attached Storage (NAS) drives, or pivoting into primary workstations.
As regulatory bodies and major tech platforms grapple with the influx of pre-infected hardware, the onus remains heavily on the consumer. Until e-commerce giants implement rigorous vendor vetting to purge counterfeit and backdoored IoT hardware from their digital shelves, vigilance remains the single most effective defense against the hidden economies of shadow streams and digital ad fraud.
